Indian Healthcare Faced Enormous Cyber Attacks in 2022, Till Nov: CyberPeace Foundation and Autobot Infosec Report

Date:

Trending

Cyber attacks on healthcare facilities have been rising in recent years, and the pandemic has only worsened matters. With hospitals and other healthcare facilities struggling to keep up with the demand for care, they have become an easy target for cybercriminals. While this may seem like a small amount, it can be devastating for a hospital that is already stretched thin.

- Advertisement -

Research done by CyberPeace Foundation (CPF), Autobot Infosec Private Limited, along with the academic partners under CyberPeace Center of Excellence (CCoE), has found that nearly 1.9 million attack events have been recorded in 2022 till 28th November on the Healthcare based threat intelligence sensors network simulated by the research group in India.

The study is a part of CyberPeace Foundation’s e-Kawach program to implement comprehensive public network and threat intelligence sensors across the country to capture internet traffic and analyze real-time cyberattacks that a location or an organization faces. A credible intelligence on real-time threats empowers organizations or a Country to build cybersecurity policies.

- Advertisement -

“By deploying the simulated network, we can collect data on attack patterns, the different types of attack vector for the different protocols, and the recent trends of malicious activity,” – Spokesperson, CyberPeace Foundation added.

Trends noticed by the Research

Like any other critical infrastructure worldwide, the Indian Healthcare infrastructure is also vulnerable to cyber attacks involving state & non-state actors. The Healthcare based threat intelligence sensors network deployed by the CyberPeace Foundation, Autobot Infosec Private Ltd. with the CyberPeace Center of Excellence (CCoE) partners has seen a surge in the number of cyberattacks with 1846712 hits between January 2022 to November 28th 2022 from a total number of 41181 Unique IP addresses appearing from countries like Vietnam, Pakistan, China etc.

The vulnerable internet-facing systems having Remote Desktop Protocol (RDP), vulnerable SMB and Database services enabled, and old Windows server Platforms were mostly attacked. Attackers also tried to inject malicious payloads into the network. The deployed network has captured a total of 1527 unique payloads belonging to Trojan, Ransomware, etc.

Analysis of data has drawn the attention that attackers also tried to exploit DICOM/MYSQL/MSSQL protocols to access the sensitive patients data like medical images, diagnostic databases etc. DICOM is standard protocol used in most medical and healthcare facilities for the management and transmission of medical images and related data.

Research team noticed a massive brute force, dictionary attacks were performed against the protocols FTP, MYSQL and MSSQL using some common credentials like ‘root’, ‘ftp’, ‘admin’, ‘web’, ‘web!’, ‘qwerty’, ‘password1’, ‘sql2005’, ‘passw0rd’, ‘administrator’ etc. One new trend has been noticed that attackers are nowadays using long passwords, not usually mentioned in the English dictionary, for example ‘4yqbm4,m~!@~#$%^&*(),.;’ and ‘!@#$%^&*’. Some common FTP commands were also captured – “USER”, “PASS”, “PWD”, “CWD”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “PASV”, “STOR”, “TYPE”.

In an earlier report released in August 2022, CyberPeace of Foundation also mentioned that there has been an increase in the number of phishing/social engineering attacks on Indian organizations in the Healthcare business. CPF spokesperson drew attention to WhatsApp messages masquerading as an offer from Apollo Hospital with links luring unsuspecting users with the promise of medical subsidy presents making the rounds on the app.

Recently, news has been making the rounds on the internet that All India Institute of Medical Sciences (AIIMS), Delhi faced a Cyberattack probably with the injected Ransomware on their systems.

“Cyber criminals are taking advantage of the fact that healthcare organizations are under immense strain and are more likely to pay a ransom to get their systems up and running again. Organisations should ensure their systems are secured by reducing unnecessary data, improving the patch level of software, backup and restore procedures and auditing systems to build awareness of any threats,” – Spokesperson added.

The Advisory

Do not expose critical services unnecessarily to the internet.

Network firewalls should always be patched with the latest security updates.

Isolate the critical network from the public network.

Periodically perform technical audits of Healthcare Infrastructure Devices, networks and any other end-points directly or indirectly connected to it, to identify security concerns.

Run CyberAwareness Drive by Cyber Experts at regular intervals for the team.

Develop an R&D lab to enhance CyberSecurity skills among the employees.

Maintain strong Password Policy:

Use a strong password for all devices and online accounts.

Passwords should be at least 8-13 characters long.

Passwords should contain at least one upper case (A-Z), numeric character (0-9), and a special character (!@%&….).

Where possible it is recommended to use key based authentication along with passwords.

Do not use the same password for all your online accounts. All the passwords should be different for different versions.

Try avoiding a password that consists of dictionary words.

Stay away from Phishing links: Phishing is an attempt of social engineering techniques to inject malware or obtain sensitive information such as usernames, passwords, and credit card information by spreading fake links and pretending to be acting as a trustworthy entity. Please do not click on such links before verifying the authenticity of the same.

Never share or forward fake messages containing links to any social platform without proper verification.

For more details, reach out to us at secretariat@cyberpeace.net.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

- Advertisement -

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

More Latest Stories

More Articles

00:01:37

UK PM Kier Starmer Abolishes NHS England To Bring Health Services Under Govt Control

British Prime Minister Keir Starmer has announced plans to abolish NHS England and bring it back under government control. The move aims to reduce...

VIDEO: US President Donald Trump Calls NBC A ‘Work Network’ On Television

During a press meeting at the Oval Office on Wednesday, US President Donald Trump criticized a reporter by calling NBC the 'worst network' on television. https://creators.spotify.com/pod/show/techgraph/episodes/VIDEO-US-President-Donald-Trump-Calls-NBC-A-Work-Network-On-Television--News--US-News-e304h89

The Role of Edge Computing in AI-Powered Cloud Solutions

With businesses including artificial intelligence (AI) in their operations, cloud computing has grown in...

From Startup to Success: Essential Steps for Landscaping Entrepreneurs

Starting a landscaping business is so exciting, blending creativity with the reward of transforming...
00:03:00

Trump Defends Elon Musk Plan for Federal Job Cuts; Govt Spending ‘Bloated’

Following a meeting with Elon Musk and senior cabinet members, U.S. President Donald Trump...
00:08:45

Trade War: Canadian PM Justin Trudeau Announces 25% Tariffs On US Imports

Ottawa: Canadian Prime Minister Justin Trudeau on Wednesday announced a 25% tariff on U.S....

Meta CPO Chris Cox Sells Shares Worth $8.3 Mn

Meta Platforms (NASDAQ: META) Chief Product Officer Christopher Cox sold 13,556 shares of the...

Meta COO Javier Olivan Offloads Shares Worth $409,768

Meta Platforms (NASDAQ: META) Chief Operating Officer Javier Olivan is set to sell 608...
00:02:23

‘Canada Ripping Us’: US President Trump Criticizes High Tariffs on Dairy and Lumber

U.S. President Donald Trump on Friday slammed Canada’s high tariffs on American dairy and lumber products, warning of retaliatory measures unless the tariffs are...

Personal branding: designing logos for influencers and creators

In today’s digital landscape, personal branding has become more than just a buzzword; it’s...

Demand for plumbers in Oman: which specialists are most in demand?

The demand for skilled plumbers in Oman is steadily increasing due to the country's...

Union Budget 2025: Real Estate Experts See SWAMIH 2.0, ₹15,000 Cr State Support to Ease Housing Bottlenecks

The real estate sector views the Union Budget 2025-26 as a step toward addressing...

Logistic Startup Picckup Secures $500K in Seed Funding to Expand Electric Fleet

A Mohali-based mid-mile and last-mile logistic startup, Picckup, on Thursday, raised $500K in series...

Empowering Communities with Water Tech

This is a major problem worldwide; it affects billions of people in homes, villages, and towns. Population increases, climate change and limited water resources...

IIT Madras and SPF Partners to Enhance Policy Framework for Indian Startups

Indian Institute of Technology Madras (IIT Madras) has entered into a Memorandum of Understanding (MoU) with the Startup Policy Forum (SPF) to drive data-driven and evidence-driven policy advocacy for the startup ecosystem. As part of this partnership, SPF will support the Centre for Research on...

Sachin Tendulkar Backed RRP Electronics Partners with Deca Technologies To Enhance Semiconductor Packaging

Cricketing legend Sachin Tendulkar-backed semiconductor manufacturer RRP Electronics has signed a strategic partnership with...

Ways Technology Can Help Your Business Performance

Businesses of all sizes and across every industry are integrating technology to improve their...

BC Originals: Exclusive Casino Games on BC.Game

BC Originals are special, exclusive casino games that are just for BC.Game players. All...

Dogsee Chew draws $8 Mn in series B round from Ektha & Others

Natural pet treat brand Dogsee Chew on Thursday said, it has raised $8 million...

Simplifying International Transfers: A New Era for Indian Immigrants in Canada

Every year, thousands of Indian professionals and families pack their lives into suitcases and...

Lado Okhotnikov: A Successful Entrepreneur Who Has Inspired Millions

Lado Okhotnikov is a successful entrepreneur, expert, publicist, and investor from Kazakhstan, widely recognized...

Choosing the Right Tax Consultant: A Guide for Businesses and Individuals

For both individuals and businesses, tax planning and compliance are crucial aspects of financial...

Life Insurance Death Benefit Payouts: What Your Family Needs to Know

It is important to know more about life insurance policies and their operational modalities....

The Rise of Conversational AI: What It Means for Tech and SaaS Businesses

Back in the time, when AI was not as prominent, businesses used to struggle...

Union Budget 2025: Real Estate Experts See SWAMIH 2.0, ₹15,000 Cr State Support to Ease Housing Bottlenecks

The real estate sector views the Union Budget 2025-26 as a step toward addressing...

Microsoft Makes Equity Investment in Veeam

American tech giant Microsoft has made an equity investment in Veeam Software to develop...

Adani Wilmar Gets Shareholders’ Approval to Rebrand as AWL Agri Business Limited

Stock exchange-listed Adani Wilmar Limited announced on Tuesday that it has received approval from...

Beyond Firewalls: How Threat Intelligence Platforms Are Transforming Cybersecurity Operations

“Cybersecurity isn't just about building walls—it’s about seeing the enemy before they strike.” In...

Leveraging AI and Modern HR Solutions to Transform Recruitment Strategies for Skilled Workers

In today’s competitive job market, recruitment strategies are rapidly evolving, driven by advancements in...

Logistic Startup Picckup Secures $500K in Seed Funding to Expand Electric Fleet

A Mohali-based mid-mile and last-mile logistic startup, Picckup, on Thursday, raised $500K in series...

Life Insurance Death Benefit Payouts: What Your Family Needs to Know

It is important to know more about life insurance policies and their operational modalities....

Wired vs. Wireless Headsets: A Comparative Guide for Evolving Audio Needs

Across a wide range of demographics, including gamers, fitness enthusiasts, business executives, and remote...

The Rise of Conversational AI: What It Means for Tech and SaaS Businesses

Back in the time, when AI was not as prominent, businesses used to struggle...